Networking & Firewall (Ss/Netstat/Iptables/Nftables/Curl)
Stop letting your webhooks die in silence behind silent packet drops
đź§© The Challenge
Dealing with a service that refuses to talk to an external API is bad enough, but when the logs show absolutely nothing useful, you end up staring at a blinking cursor for an hour. It’s always the firewall getting in the way, but you can’t see the silent drops.
đź’ˇ The Fix
Use the trace command in nftables to catch those packets red-handed as they hit your ruleset. It shows you exactly which line of the firewall logic is sending your traffic into the void.
nft monitor trace
nft add rule ip filter output tcp dport 443 meta nftrace set 1
⚙️ Why It Works
Setting the trace metadata bit tells the kernel to log every single rule that matches a specific packet. You get a real-time feed of how the packet traverses the chain so you aren’t left guessing which drop rule finally killed it.
🚀 Pro-Tip: Remember to turn it off when you’re done, or you’ll be debugging logs until next Tuesday.
Linux Tips & Tricks | © ngelinux.com | 9/30/2026
